Insider Threat Defense Strategies: Survey and Knowledge Integration
摘要
Insider threats are one of the most challenging cybersecurity issues today, and are receiving increasing attention both in the computer science community and in the government and corporate world. In this study, we provide a comprehensive overview of existing scholarly investigations that employ structural taxonomies. Our objective is to systematize and distinguish insider threat events and the corresponding defense mechanisms. We conduct a comprehensive analysis of defense strategies against insider threats, encompassing preventive and detection methods. Subsequently, we present a detailed taxonomy focused on workflow processes, organizing defense and mitigation measures at each stage of an insider threat’s lifecycle. The presented taxonomy provides a detailed description of defense and mitigation measures applicable at each stage in the life cycle of internal threats. Special attention is paid to the external knowledge bases for assisting the model in determining insider threat behaviors. Our survey aims to augment the practitioners in the insider threat domain by offering (1) a workflow-centric structural taxonomy that contributes to the orthogonal classification of incidents and delineates the scope of defense solutions utilized to counter them, (2) an overview on publicly available datasets for model performance comparison, (3) a compilation of external knowledge bases used to aid insider threat detection, and (4) a discussion of existing trends and further research directions in the insider threat domain.